Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.wso2/carbon-apimgt

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-3415 is a high-severity vulnerability in WSO2 API Manager affecting multiple versions. It involves improper handling of special elements in XML Document Type Declarations (DTD) during schema validation, allowing an XML parser to resolve external entities when processing user-supplied XML. This can enable a highly privileged attacker to read files on the server, cause outbound network requests to unintended locations, or trigger resource exhaustion impacting availability.

Join the discussion

CVE-2025-14561 is a critical improper access control vulnerability in WSO2 API Manager affecting multi-tenant deployments. The Publisher REST APIs do not properly enforce tenant isolation, allowing a privileged user in one tenant to perform publisher operations such as exposing or modifying API metadata in other tenants. This issue impacts versions 4.1.0 through 4.6.0. The vulnerability has a CVSS score of 9.0, indicating high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

CVE-2026-1728 is a critical vulnerability in WSO2 API Manager where tokens issued to low-privileged users are not sufficiently restricted. This flaw allows these tokens to access product-level Admin REST APIs, potentially enabling an attacker with a low-privileged account to escalate privileges to full administrative control. The vulnerability affects multiple specific versions of WSO2 API Manager. No official patch or remediation guidance has been provided yet.

Join the discussion

CVE-2026-0637 is a vulnerability in WSO2 API Manager where misconfigured Event Publisher output adapters log sensitive information without proper validation or sanitization. This can lead to sensitive data, such as user credentials, being stored in log files accessible to users with access to the 'wso2carbon' logs. The vulnerability has a medium severity rating with a CVSS score of 4.4.

Join the discussion

CVE-2024-10302 is a medium severity vulnerability in WSO2 API Control Plane version 4.5.0 involving improper input validation in the user self-signup flow. Unvalidated user-supplied data can be included in user claims, which downstream processes consume. This may lead to security risks such as content manipulation, redirection, UI inconsistencies, unauthorized actions, and data exposure depending on how the data is used and the privileges of affected users. No official patch or remediation guidance is currently available.

Join the discussion

WSO2 API Manager versions 3.1.0 through 4.6.0 have a vulnerability where unused authorization codes issued to deleted users are not properly invalidated. This allows these codes to persist and potentially be reused by attackers who have the authorization code and client credentials, enabling unauthorized access to resources within the scope of the original authorization.

Join the discussion

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.

Join the discussion

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Join the discussion

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a malicious website, manipulation of the web page's user interface, or the retrieval of information from the browser. However, session hijacking is not possible due to the httpOnly flag protecting session-related cookies.

Join the discussion

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an attacker to redirect the user's browser to a malicious website, modify the UI of the web page, or retrieve information from the browser. However, the impact is limited as session-related sensitive cookies are protected by the httpOnly flag, preventing session hijacking.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:maven/org.wso2/carbon-apimgt
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses